Dlink Di-8003 Firmware vulnerabilities
35 known vulnerabilities affecting dlink/di-8003_firmware.
Total CVEs
35
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH28MEDIUM3
Vulnerabilities
Page 1 of 2
CVE-2024-11046P2CRITICALCVSS 9.8v16.07.16a12024-11-10
CVE-2024-11046 [CRITICAL] CWE-77 CVE-2024-11046: A vulnerability was found in D-Link DI-8003 16.07.16A1. It has been classified as critical. Affected
A vulnerability was found in D-Link DI-8003 16.07.16A1. It has been classified as critical. Affected is the function upgrade_filter_asp of the file /upgrade_filter.asp. The manipulation of the argument path leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
nvd
CVE-2024-52759P2CRITICALCVSS 9.8v16.07.16a12024-11-19
CVE-2024-52759 [CRITICAL] CWE-120 CVE-2024-52759: D-LINK DI-8003 v16.07.26A1 was discovered to contain a buffer overflow via the ip parameter in the i
D-LINK DI-8003 v16.07.26A1 was discovered to contain a buffer overflow via the ip parameter in the ip_position_asp function.
nvd
CVE-2024-11047P2CRITICALCVSS 9.8v16.07.16a12024-11-10
CVE-2024-11047 [CRITICAL] CWE-119 CVE-2024-11047: A vulnerability was found in D-Link DI-8003 16.07.16A1. It has been declared as critical. Affected b
A vulnerability was found in D-Link DI-8003 16.07.16A1. It has been declared as critical. Affected by this vulnerability is the function upgrade_filter_asp of the file /upgrade_filter.asp. The manipulation of the argument path leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public an
nvd
CVE-2024-11048P2CRITICALCVSS 9.8v16.07.16a12024-11-10
CVE-2024-11048 [CRITICAL] CWE-119 CVE-2024-11048: A vulnerability was found in D-Link DI-8003 16.07.16A1. It has been rated as critical. Affected by t
A vulnerability was found in D-Link DI-8003 16.07.16A1. It has been rated as critical. Affected by this issue is the function dbsrv_asp of the file /dbsrv.asp. The manipulation of the argument str leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
nvd
CVE-2025-50664P3HIGHCVSS 7.5v16.07.26a12026-04-08
CVE-2025-50664 [HIGH] CWE-121 CVE-2025-50664: A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of para
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /user_group.asp endpoint. The attacker can exploit this vulnerability by sending a crafted HTTP GET request with parameters name, mem, pri, and attr.
nvd
CVE-2025-50661P3HIGHCVSS 7.5v16.07.26a12026-04-08
CVE-2025-50661 [HIGH] CWE-121 CVE-2025-50661: A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of mult
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of multiple parameters in the /url_rule.asp endpoint. An attacker can exploit this vulnerability by sending a crafted HTTP GET request with parameters name, en, ips, u, time, act, rpri, and log.
nvd
CVE-2025-50665P3HIGHCVSS 7.5v16.07.26a12026-04-08
CVE-2025-50665 [HIGH] CWE-120 CVE-2025-50665: A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of inpu
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of input parameters in the /web_keyword.asp endpoint. An attacker can exploit this vulnerability by sending a crafted HTTP GET request via the name, en, time, mem_gb2312, and mem_utf8 parameters.
nvd
CVE-2025-50666P3HIGHCVSS 7.5v16.07.26a12026-04-08
CVE-2025-50666 [HIGH] CWE-120 CVE-2025-50666: A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of mult
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of multiple parameters in the /web_post.asp endpoint. An attacker can exploit this vulnerability by sending a crafted HTTP GET request in parameters such as name, en, user_id, log, and time.
nvd
CVE-2025-50671P3HIGHCVSS 7.5v16.07.26a12026-04-08
CVE-2025-50671 [HIGH] CWE-121 CVE-2025-50671: A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of para
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /xwgl_ref.asp endpoint. An attacker can exploit this vulnerability by sending a crafted HTTP GET request with excessively long strings in parameters name, en, user_id, shibie_name, time, act, log, and rpri.
nvd
CVE-2025-50645P3HIGHCVSS 7.5v16.07.26a12026-04-08
CVE-2025-50645 [HIGH] CWE-120 CVE-2025-50645: A vulnerability has been discovered in D-Link DI-8003 16.07.26A1, which can lead to a buffer overflo
A vulnerability has been discovered in D-Link DI-8003 16.07.26A1, which can lead to a buffer overflow when the s parameter in the pppoe_list_opt.asp endpoint is manipulated. By sending a crafted request with an excessively large value for the s parameter, an attacker can trigger a buffer overflow condition.
nvd
CVE-2025-50670P3HIGHCVSS 7.5v16.07.26a12026-04-08
CVE-2025-50670 [HIGH] CWE-120 CVE-2025-50670: A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of para
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /xwgl_bwr.asp endpoint. An attacker can exploit this vulnerability by sending a crafted HTTP GET request in the name, qq, and time parameters.
nvd
CVE-2025-50655P3HIGHCVSS 7.5v16.07.26a12026-04-08
CVE-2025-50655 [HIGH] CWE-121 CVE-2025-50655: A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name parameter in the /thd_group.asp endpoint.
nvd
CVE-2025-50647P3HIGHCVSS 7.5v16.07.26a12026-04-08
CVE-2025-50647 [HIGH] CWE-120 CVE-2025-50647: A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1, specifically in the handling of
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1, specifically in the handling of the wans parameter in the qos.asp endpoint.
nvd
CVE-2025-50649P3HIGHCVSS 7.5v16.07.26a12026-04-08
CVE-2025-50649 [HIGH] CWE-120 CVE-2025-50649: A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper input validation
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper input validation in the vlan_name parameter in the /shut_set.asp endpoint.
nvd
CVE-2025-50660P3HIGHCVSS 7.5v16.07.26a12026-04-08
CVE-2025-50660 [HIGH] CWE-121 CVE-2025-50660: A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name parameter in the /url_member.asp endpoint.
nvd
CVE-2025-50650P3HIGHCVSS 7.5v16.07.26a12026-04-08
CVE-2025-50650 [HIGH] CWE-120 CVE-2025-50650: A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to inadequate validation of
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to inadequate validation of input size in the routes_static parameter in the /router.asp endpoint.
nvd
CVE-2025-50662P3HIGHCVSS 7.5v16.07.26a12026-04-08
CVE-2025-50662 [HIGH] CWE-121 CVE-2025-50662: A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name parameter in the /url_group.asp endpoint.
nvd
CVE-2025-50663P3HIGHCVSS 7.5v16.07.26a12026-04-08
CVE-2025-50663 [HIGH] CWE-121 CVE-2025-50663: A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name parameter in the /usb_paswd.asp endpoint.
nvd
CVE-2025-50646P3HIGHCVSS 7.5v16.07.26a12026-04-08
CVE-2025-50646 [HIGH] CWE-120 CVE-2025-50646: A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to insufficient input valida
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to insufficient input validation on the name parameter in the /qos_type_asp.asp endpoint.
nvd
CVE-2025-50659P3HIGHCVSS 7.5v16.07.26a12026-04-08
CVE-2025-50659 [HIGH] CWE-121 CVE-2025-50659: A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the custom_error parameter in the /user.asp endpoint.
nvd
1 / 2Next →